{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T21:23:20Z","timestamp":1783632200987,"version":"3.55.0"},"reference-count":92,"publisher":"Springer Science and Business Media LLC","issue":"7","license":[{"start":{"date-parts":[[2024,4,25]],"date-time":"2024-04-25T00:00:00Z","timestamp":1714003200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,4,25]],"date-time":"2024-04-25T00:00:00Z","timestamp":1714003200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cluster Comput"],"published-print":{"date-parts":[[2024,10]]},"DOI":"10.1007\/s10586-024-04430-6","type":"journal-article","created":{"date-parts":[[2024,4,25]],"date-time":"2024-04-25T16:04:10Z","timestamp":1714061050000},"page":"9635-9661","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":23,"title":["Intrusion detection systems for software-defined networks: a comprehensive study on machine learning-based techniques"],"prefix":"10.1007","volume":"27","author":[{"given":"Zaid","family":"Mustafa","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rashid","family":"Amin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hamza","family":"Aldabbas","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Naeem","family":"Ahmed","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,4,25]]},"reference":[{"issue":"4","key":"4430_CR1","doi-asserted-by":"publisher","first-page":"3542","DOI":"10.1109\/COMST.2018.2839348","volume":"20","author":"A Abdou","year":"2018","unstructured":"Abdou, A., Oorschot, P.C., Wan, T.: Comparative analysis of control plane security of SDN and conventional networks. IEEE Commun. Surv. Tutor. 20(4), 3542\u20133559 (2018). https:\/\/doi.org\/10.1109\/COMST.2018.2839348","journal-title":"IEEE Commun. Surv. Tutor."},{"issue":"10","key":"4430_CR2","doi-asserted-by":"publisher","DOI":"10.1016\/j.asej.2023.102211","volume":"14","author":"RA Elsayed","year":"2023","unstructured":"Elsayed, R.A., Hamada, R.A., Abdalla, M.I., Elsaid, S.A.: Securing IoT and SDN systems using deep-learning based automatic intrusion detection. Ain Shams Eng. J. 14(10), 102211 (2023)","journal-title":"Ain Shams Eng. J."},{"issue":"6","key":"4430_CR3","doi-asserted-by":"publisher","first-page":"1994","DOI":"10.1109\/JIOT.2017.2746186","volume":"4","author":"S Bera","year":"2017","unstructured":"Bera, S., Misra, S., Vasilakos, A.V.: Software-defined networking for internet of things: a survey. IEEE Internet Things J. 4(6), 1994\u20132008 (2017). https:\/\/doi.org\/10.1109\/JIOT.2017.2746186","journal-title":"IEEE Internet Things J."},{"key":"4430_CR4","doi-asserted-by":"publisher","first-page":"189","DOI":"10.1201\/9781003216971-11","volume-title":"Data-Driven Intelligence in Wireless Networks","author":"R Amin","year":"2023","unstructured":"Amin, R., Hussain, M., Bibi, S., Sabir, A.: Policy-based data analytic for software defined wireless sensor networks. In: Afzal, M.K., Ateeq, M., Kim, S.W. (eds.) Data-Driven Intelligence in Wireless Networks, pp. 189\u2013212. CRC Press, Boca Raton (2023)"},{"key":"4430_CR5","doi-asserted-by":"crossref","unstructured":"Huang, C.-H., Lee, T.-H., Chang, L.-H., Lin, J.-R., Horng, G.: Adversarial attacks on SDN-based deep learning ids system. (2018)","DOI":"10.1007\/978-981-13-1059-1_17"},{"issue":"3","key":"4430_CR6","doi-asserted-by":"publisher","first-page":"1701","DOI":"10.1109\/COMST.2017.2689819","volume":"19","author":"T Dargahi","year":"2017","unstructured":"Dargahi, T., Caponi, A., Ambrosin, M., Bianchi, G., Conti, M.: A survey on the security of stateful SDN data planes. IEEE Commun. Surv. Tutor. 19(3), 1701\u20131725 (2017). https:\/\/doi.org\/10.1109\/COMST.2017.2689819","journal-title":"IEEE Commun. Surv. Tutor."},{"issue":"2","key":"4430_CR7","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1109\/IOTM.003.2200001","volume":"5","author":"V Ravi","year":"2022","unstructured":"Ravi, V., Chaganti, R., Alazab, M.: Deep learning feature fusion approach for an intrusion detection system in SDN-based IoT networks. IEEE Internet Things Mag. 5(2), 24\u201329 (2022)","journal-title":"IEEE Internet Things Mag."},{"issue":"1","key":"4430_CR8","doi-asserted-by":"publisher","first-page":"333","DOI":"10.1109\/COMST.2017.2782482","volume":"20","author":"F Bannour","year":"2018","unstructured":"Bannour, F., Souihi, S., Mellouk, A.: Distributed SDN control: survey, taxonomy, and challenges. IEEE Commun. Surv. Tutor. 20(1), 333\u2013354 (2018). https:\/\/doi.org\/10.1109\/COMST.2017.2782482","journal-title":"IEEE Commun. Surv. Tutor."},{"issue":"1","key":"4430_CR9","doi-asserted-by":"publisher","first-page":"867","DOI":"10.32604\/iasc.2023.026769","volume":"35","author":"G Logeswari","year":"2023","unstructured":"Logeswari, G., Bose, S., Anitha, T.: An intrusion detection system for SDN using machine learning. Intell. Autom. Soft Comput. 35(1), 867\u2013880 (2023)","journal-title":"Intell. Autom. Soft Comput."},{"issue":"4","key":"4430_CR10","doi-asserted-by":"publisher","first-page":"3259","DOI":"10.1109\/COMST.2018.2837161","volume":"20","author":"R Amin","year":"2018","unstructured":"Amin, R., Reisslein, M., Shah, N.: Hybrid SDN networks: a survey of existing approaches. IEEE Commun. Surv. Tutor. 20(4), 3259\u20133306 (2018). https:\/\/doi.org\/10.1109\/COMST.2018.2837161","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"4430_CR11","doi-asserted-by":"publisher","unstructured":"Mohammed, A.R., Mohammed, S.A., Shirmohammadi, S.: Machine learning and deep learning based traffic classification and prediction in software defined networking. In: 2019 IEEE International Symposium on Measurements Networking (M N), pp. 1\u20136 (2019). https:\/\/doi.org\/10.1109\/IWMN.2019.8805044","DOI":"10.1109\/IWMN.2019.8805044"},{"issue":"3","key":"4430_CR12","doi-asserted-by":"publisher","first-page":"1869","DOI":"10.32604\/cmc.2020.011758","volume":"65","author":"R Amin","year":"2020","unstructured":"Amin, R., Hussain, M., Alhameed, M., Raza, S.M., Jeribi, F., Tahir, A.: Edge-computing with graph computation: a novel mechanism to handle network intrusion and address spoofing in SDN. Comput. Mater. Continua 65(3), 1869\u20131890 (2020)","journal-title":"Comput. Mater. Continua"},{"issue":"10","key":"4430_CR13","doi-asserted-by":"publisher","first-page":"126","DOI":"10.1364\/JOCN.10.00D126","volume":"10","author":"D Rafique","year":"2018","unstructured":"Rafique, D., Velasco, L.: Machine learning for network automation: overview, architecture, and applications [invited tutorial]. IEEE\/OSA J. Opt. Commun. Netw. 10(10), 126\u2013143 (2018). https:\/\/doi.org\/10.1364\/JOCN.10.00D126","journal-title":"IEEE\/OSA J. Opt. Commun. Netw."},{"key":"4430_CR14","doi-asserted-by":"crossref","unstructured":"Ali, F.S., Amin, R., Majeed, M., Iqbal, M.M.: Dynamic acl policy implementation in software defined networks. In: 2022 International Conference on IT and Industrial Technologies (ICIT), IEEE. pp. 01\u201307 (2022)","DOI":"10.1109\/ICIT56493.2022.9989241"},{"issue":"3","key":"4430_CR15","doi-asserted-by":"publisher","first-page":"2269","DOI":"10.1109\/TNSM.2022.3175710","volume":"19","author":"L Yang","year":"2022","unstructured":"Yang, L., Song, Y., Gao, S., Hu, A., Xiao, B.: Griffin: real-time network intrusion detection system via ensemble of autoencoder in SDN. IEEE Trans. Netw. Serv. Manag. 19(3), 2269\u20132281 (2022)","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"4430_CR16","unstructured":"Jamshidi, S.: The applications of machine learning techniques in networking (2019)"},{"key":"4430_CR17","doi-asserted-by":"publisher","unstructured":"Abar, T., Ben\u00a0Letaifa, A., El\u00a0Asmi, S.: Machine learning based QOE prediction in SDN networks. In: 2017 13th International Wireless Communications and Mobile Computing Conference (IWCMC), pp. 1395\u20131400 (2017). https:\/\/doi.org\/10.1109\/IWCMC.2017.7986488","DOI":"10.1109\/IWCMC.2017.7986488"},{"key":"4430_CR18","doi-asserted-by":"publisher","unstructured":"Jain, S., Khandelwal, M., Katkar, A., Nygate, J.: Applying big data technologies to manage qos in an sdn. In: 2016 12th International Conference on Network and Service Management (CNSM), pp. 302\u2013306 (2016). https:\/\/doi.org\/10.1109\/CNSM.2016.7818437","DOI":"10.1109\/CNSM.2016.7818437"},{"key":"4430_CR19","doi-asserted-by":"publisher","DOI":"10.14569\/IJACSA.2017.080474","author":"F Ubaid","year":"2017","unstructured":"Ubaid, F., Amin, R., Ubaid, F.B., Iqbal, M.M.: Mitigating address spoofing attacks in hybrid SDN. Int. J. Adv. Comput. Sci. Appl. (2017). https:\/\/doi.org\/10.14569\/IJACSA.2017.080474","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"issue":"4","key":"4430_CR20","doi-asserted-by":"publisher","first-page":"2753","DOI":"10.1007\/s11277-022-10069-6","volume":"128","author":"HA Hassan","year":"2023","unstructured":"Hassan, H.A., Hemdan, E.E., El-Shafai, W., Shokair, M., El-Samie, F.E.A.: Intrusion detection systems for the internet of thing: a survey study. Wirel. Pers. Commun. 128(4), 2753\u20132778 (2023)","journal-title":"Wirel. Pers. Commun."},{"issue":"3","key":"4430_CR21","doi-asserted-by":"publisher","first-page":"23","DOI":"10.11113\/elektrika.v21n3.361","volume":"21","author":"SH Ariffin","year":"2022","unstructured":"Ariffin, S.H., Le Chong, J., Latif, N.M.A., Abd Malik, N.N.N., Baharudin, M.A., Syed-Yusof, S.K., Yusof, K.M., et al.: Intrusion detection system (IDS) accuracy testing for software defined network internet of things (SDN-IoT) testbed. ELEKTRIKA 21(3), 23\u201327 (2022)","journal-title":"ELEKTRIKA"},{"key":"4430_CR22","doi-asserted-by":"publisher","first-page":"9437","DOI":"10.1109\/ACCESS.2016.2641482","volume":"4","author":"R Amin","year":"2016","unstructured":"Amin, R., Shah, N., Shah, B., Alfandi, O.: Auto-configuration of ACL policy in case of topology change in hybrid SDN. IEEE Access 4, 9437\u20139450 (2016). https:\/\/doi.org\/10.1109\/ACCESS.2016.2641482","journal-title":"IEEE Access"},{"key":"4430_CR23","doi-asserted-by":"publisher","DOI":"10.3390\/electronics8060604","author":"R Amin","year":"2019","unstructured":"Amin, R., Shah, N., Mehmood, W.: Enforcing optimal ACL policies using k-partite graph in hybrid SDN. Electronics (2019). https:\/\/doi.org\/10.3390\/electronics8060604","journal-title":"Electronics"},{"key":"4430_CR24","doi-asserted-by":"publisher","unstructured":"Mousavi, S.M., St-Hilaire, M.: Early detection of DDOS attacks against SDN controllers. In: 2015 International Conference on Computing, Networking and Communications (ICNC), pp. 77\u201381 (2015). https:\/\/doi.org\/10.1109\/ICCNC.2015.7069319","DOI":"10.1109\/ICCNC.2015.7069319"},{"key":"4430_CR25","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101636","volume":"88","author":"MM Yamin","year":"2020","unstructured":"Yamin, M.M., Katt, B., Gkioulos, V.: Cyber ranges and security testbeds: Scenarios, functions, tools and architecture. Comput. Secur. 88, 101636 (2020). https:\/\/doi.org\/10.1016\/j.cose.2019.101636","journal-title":"Comput. Secur."},{"key":"4430_CR26","doi-asserted-by":"publisher","unstructured":"Chin, T., Mountrouidou, X., Li, X., Xiong, K.: Selective packet inspection to detect dos flooding using software defined networking (SDN). In: 2015 IEEE 35th International Conference on Distributed Computing Systems Workshops, pp. 95\u201399 (2015). https:\/\/doi.org\/10.1109\/ICDCSW.2015.27","DOI":"10.1109\/ICDCSW.2015.27"},{"issue":"6","key":"4430_CR27","doi-asserted-by":"publisher","first-page":"5141","DOI":"10.1109\/JIOT.2018.2838574","volume":"5","author":"F Tang","year":"2018","unstructured":"Tang, F., Fadlullah, Z.M., Mao, B., Kato, N.: An intelligent traffic load prediction-based adaptive channel assignment algorithm in SDN-IoT: a deep learning approach. IEEE Internet Things J. 5(6), 5141\u20135154 (2018). https:\/\/doi.org\/10.1109\/JIOT.2018.2838574","journal-title":"IEEE Internet Things J."},{"key":"4430_CR28","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1016\/j.iot.2018.11.003","volume":"5","author":"PI Radoglou Grammatikis","year":"2019","unstructured":"Radoglou Grammatikis, P.I., Sarigiannidis, P.G., Moscholios, I.D.: Securing the internet of things: challenges, threats and solutions. Internet Things 5, 41\u201370 (2019). https:\/\/doi.org\/10.1016\/j.iot.2018.11.003","journal-title":"Internet Things"},{"issue":"4","key":"4430_CR29","doi-asserted-by":"publisher","first-page":"713","DOI":"10.1016\/j.eswa.2005.05.002","volume":"29","author":"O Depren","year":"2005","unstructured":"Depren, O., Topallar, M., Anarim, E., Ciliz, M.K.: An intelligent intrusion detection system (IDS) for anomaly and misuse detection in computer networks. Expert Syst. Appl. 29(4), 713\u2013722 (2005). https:\/\/doi.org\/10.1016\/j.eswa.2005.05.002","journal-title":"Expert Syst. Appl."},{"issue":"1","key":"4430_CR30","doi-asserted-by":"publisher","first-page":"393","DOI":"10.1109\/COMST.2018.2866942","volume":"21","author":"J Xie","year":"2019","unstructured":"Xie, J., Yu, F.R., Huang, T., Xie, R., Liu, J., Wang, C., Liu, Y.: A survey of machine learning techniques applied to software defined networking (SDN): research issues and challenges. IEEE Commun. Surv. Tutor. 21(1), 393\u2013430 (2019). https:\/\/doi.org\/10.1109\/COMST.2018.2866942","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"4430_CR31","doi-asserted-by":"publisher","unstructured":"Hussain, M., Shah, N.: Automatic rule installation in case of policy change in software defined networks (2018). https:\/\/doi.org\/10.1007\/s11235-017-0404-2","DOI":"10.1007\/s11235-017-0404-2"},{"key":"4430_CR32","doi-asserted-by":"publisher","unstructured":"Shaghaghi, A., Kaafar, M.A., Buyya, R., Jha, S.: In: Gupta, B.B., Perez, G.M., Agrawal, D.P., Gupta, D. (eds.) Software-Defined Network (SDN) Data Plane Security: Issues, Solutions, and Future Directions, pp. 341\u2013387. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-22277-2_14","DOI":"10.1007\/978-3-030-22277-2_14"},{"key":"4430_CR33","doi-asserted-by":"publisher","unstructured":"Nanda, S., Zafari, F., DeCusatis, C., Wedaa, E., Yang, B.: Predicting network attack patterns in sdn using machine learning approach. In: 2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN), pp. 167\u2013172 (2016). https:\/\/doi.org\/10.1109\/NFV-SDN.2016.7919493","DOI":"10.1109\/NFV-SDN.2016.7919493"},{"key":"4430_CR34","unstructured":"Bai, H.: A survey on artificial intelligence for network routing problems. (2007)"},{"issue":"4","key":"4430_CR35","doi-asserted-by":"publisher","first-page":"2392","DOI":"10.1109\/COMST.2017.2727878","volume":"19","author":"PV Klaine","year":"2017","unstructured":"Klaine, P.V., Imran, M.A., Onireti, O., Souza, R.D.: A survey of machine learning techniques applied to self-organizing cellular networks. IEEE Commun. Surv. Tutor. 19(4), 2392\u20132431 (2017). https:\/\/doi.org\/10.1109\/COMST.2017.2727878","journal-title":"IEEE Commun. Surv. Tutor."},{"issue":"18","key":"4430_CR36","doi-asserted-by":"publisher","first-page":"2227","DOI":"10.1016\/j.comcom.2011.07.001","volume":"34","author":"P Sangkatsanee","year":"2011","unstructured":"Sangkatsanee, P., Wattanapongsakorn, N., Charnsripinyo, C.: Practical real-time intrusion detection using machine learning approaches. Comput. Commun. 34(18), 2227\u20132235 (2011). https:\/\/doi.org\/10.1016\/j.comcom.2011.07.001","journal-title":"Comput. Commun."},{"key":"4430_CR37","unstructured":"Scarfone, K., Mell, P.: Guide to intrusion detection and prevention systems (idps). (2012)"},{"issue":"2","key":"4430_CR38","doi-asserted-by":"publisher","first-page":"2724","DOI":"10.48084\/etasr.1840","volume":"8","author":"MHH Khairi","year":"2018","unstructured":"Khairi, M.H.H., Ariffin, S.H.S., Abdul Latiff, N.M., Abdullah, A.S., Hassan, M.K.: A review of anomaly detection techniques and distributed denial of service (DDOS) on software defined network (SDN). Eng. Technol. Appl. Sci. Res. 8(2), 2724\u20132730 (2018). https:\/\/doi.org\/10.48084\/etasr.1840","journal-title":"Eng. Technol. Appl. Sci. Res."},{"key":"4430_CR39","doi-asserted-by":"publisher","unstructured":"Shin, S., Xu, L., Hong, S., Gu, G.: Enhancing network security through software defined networking (sdn). In: 2016 25th International Conference on Computer Communication and Networks (ICCCN), pp. 1\u20139 (2016). https:\/\/doi.org\/10.1109\/ICCCN.2016.7568520","DOI":"10.1109\/ICCCN.2016.7568520"},{"key":"4430_CR40","doi-asserted-by":"publisher","unstructured":"Song, C., Park, Y., Golani, K., Kim, Y., Bhatt, K., Goswami, K.: Machine-learning based threat-aware system in software defined networks. In: 2017 26th International Conference on Computer Communication and Networks (ICCCN), pp. 1\u20139 (2017). https:\/\/doi.org\/10.1109\/ICCCN.2017.8038436","DOI":"10.1109\/ICCCN.2017.8038436"},{"issue":"4","key":"4430_CR41","doi-asserted-by":"publisher","first-page":"2451","DOI":"10.1109\/TVT.2007.912610","volume":"57","author":"RM Khanafer","year":"2008","unstructured":"Khanafer, R.M., Solana, B., Triola, J., Barco, R., Moltsen, L., Altman, Z., Lazaro, P.: Automated diagnosis for UMTS networks using Bayesian network approach. IEEE Trans. Veh. Technol. 57(4), 2451\u20132461 (2008). https:\/\/doi.org\/10.1109\/TVT.2007.912610","journal-title":"IEEE Trans. Veh. Technol."},{"key":"4430_CR42","doi-asserted-by":"publisher","unstructured":"Gangadhar, S., Sterbenz, J.P.G.: Machine learning aided traffic tolerance to improve resilience for software defined networks. In: 2017 9th International Workshop on Resilient Networks Design and Modeling (RNDM), pp. 1\u20137 (2017). https:\/\/doi.org\/10.1109\/RNDM.2017.8093035","DOI":"10.1109\/RNDM.2017.8093035"},{"key":"4430_CR43","doi-asserted-by":"publisher","first-page":"493","DOI":"10.1007\/s12083-017-0630-0","volume":"12","author":"N Sultana","year":"2019","unstructured":"Sultana, N., Chilamkurti, N., Peng, W., Alhadad, R.: Survey on SDN based network intrusion detection system using machine learning approaches. Peer-to-Peer Netw. Appl. 12, 493\u2013501 (2019)","journal-title":"Peer-to-Peer Netw. Appl."},{"key":"4430_CR44","doi-asserted-by":"publisher","unstructured":"Ashraf, J., Latif, S.: Handling intrusion and ddos attacks in software defined networks using machine learning techniques. In: 2014 National Software Engineering Conference, pp. 55\u201360 (2014). https:\/\/doi.org\/10.1109\/NSEC.2014.6998241","DOI":"10.1109\/NSEC.2014.6998241"},{"key":"4430_CR45","doi-asserted-by":"publisher","unstructured":"Nguyen, T.N.: The challenges in ml-based security for sdn. In: 2018 2nd Cyber Security in Networking Conference (CSNet), pp. 1\u20139 (2018). https:\/\/doi.org\/10.1109\/CSNET.2018.8602680","DOI":"10.1109\/CSNET.2018.8602680"},{"key":"4430_CR46","doi-asserted-by":"publisher","unstructured":"Clark, D.D., Partridge, C., Ramming, J.C., Wroclawski, J.T.: A knowledge plane for the internet. SIGCOMM \u201903, pp. 3\u201310. Association for Computing Machinery, New York, NY, USA (2003). https:\/\/doi.org\/10.1145\/863955.863957","DOI":"10.1145\/863955.863957"},{"issue":"3","key":"4430_CR47","doi-asserted-by":"publisher","first-page":"1086","DOI":"10.1109\/TR.2015.2421391","volume":"64","author":"ST Ali","year":"2015","unstructured":"Ali, S.T., Sivaraman, V., Radford, A., Jha, S.: A survey of securing networks using software defined networking. IEEE Trans. Reliab. 64(3), 1086\u20131097 (2015). https:\/\/doi.org\/10.1109\/TR.2015.2421391","journal-title":"IEEE Trans. Reliab."},{"issue":"4","key":"4430_CR48","doi-asserted-by":"publisher","first-page":"2232","DOI":"10.1109\/COMST.2017.2715220","volume":"19","author":"R Alvizu","year":"2017","unstructured":"Alvizu, R., Maier, G., Kukreja, N., Pattavina, A., Morro, R., Capello, A., Cavazzoni, C.: Comprehensive survey on T-SDN: software-defined networking for transport networks. IEEE Commun. Surv. Tutor. 19(4), 2232\u20132283 (2017). https:\/\/doi.org\/10.1109\/COMST.2017.2715220","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"4430_CR49","doi-asserted-by":"publisher","unstructured":"Wang, R., Jia, Z., Ju, L.: An entropy-based distributed ddos detection mechanism in software-defined networking. In: 2015 IEEE Trustcom\/BigDataSE\/ISPA, vol. 1, pp. 310\u2013317 (2015). https:\/\/doi.org\/10.1109\/Trustcom.2015.389","DOI":"10.1109\/Trustcom.2015.389"},{"issue":"11","key":"4430_CR50","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1109\/MCOM.2016.1600485CM","volume":"54","author":"R Huo","year":"2016","unstructured":"Huo, R., Yu, F.R., Huang, T., Xie, R., Liu, J., Leung, V.C.M., Liu, Y.: Software defined networking, caching, and computing for green wireless networks. IEEE Commun. Mag. 54(11), 185\u2013193 (2016). https:\/\/doi.org\/10.1109\/MCOM.2016.1600485CM","journal-title":"IEEE Commun. Mag."},{"key":"4430_CR51","doi-asserted-by":"publisher","unstructured":"Agarwal, S., Kodialam, M., Lakshman, T.V.: Traffic engineering in software defined networks. In: 2013 Proceedings IEEE INFOCOM, pp. 2211\u20132219 (2013). https:\/\/doi.org\/10.1109\/INFCOM.2013.6567024","DOI":"10.1109\/INFCOM.2013.6567024"},{"key":"4430_CR52","doi-asserted-by":"publisher","first-page":"3448","DOI":"10.1016\/j.comnet.2007.02.001","volume":"51","author":"A Patcha","year":"2007","unstructured":"Patcha, A., Park, J.: An overview of anomaly detection techniques: existing solutions and latest technological trends. Comput. Netw. 51, 3448\u20133470 (2007)","journal-title":"Comput. Netw."},{"key":"4430_CR53","unstructured":"Jadidi, Z., Muthukkumarasamy, V., Sithirasenan, E., Singh, K.: Based intrusion detection techniques. The State of the Art in Intrusion Prevention and Detection, 285 (2014)"},{"key":"4430_CR54","doi-asserted-by":"publisher","unstructured":"Ha, T., Kim, S., An, N., Narantuya, J., Jeong, C., Kim, J., Lim, H.: Suspicious traffic sampling for intrusion detection in software-defined networks 109(P2) (2016) https:\/\/doi.org\/10.1016\/j.comnet.2016.05.019","DOI":"10.1016\/j.comnet.2016.05.019"},{"key":"4430_CR55","volume-title":"Introduction to Machine Learning","author":"E Alpaydin","year":"2020","unstructured":"Alpaydin, E.: Introduction to Machine Learning. The MIT Press, Cambridge (2020)"},{"key":"4430_CR56","doi-asserted-by":"publisher","DOI":"10.1186\/s13174-018-0087-2","author":"R Boutaba","year":"2018","unstructured":"Boutaba, R., Salahuddin, M.A., Limam, N., Ayoubi, S., Shahriar, N., Estrada-Solano, F., Caicedo, O.M.: A comprehensive survey on machine learning for networking: evolution, applications and research opportunities. J. Internet Serv. Appl. (2018). https:\/\/doi.org\/10.1186\/s13174-018-0087-2","journal-title":"J. Internet Serv. Appl."},{"issue":"2","key":"4430_CR57","doi-asserted-by":"publisher","first-page":"92","DOI":"10.1109\/MNET.2017.1700200","volume":"32","author":"M Wang","year":"2018","unstructured":"Wang, M., Cui, Y., Wang, X., Xiao, S., Jiang, J.: Machine learning for networking: workflow, advances and opportunities. IEEE Netw. 32(2), 92\u201399 (2018). https:\/\/doi.org\/10.1109\/MNET.2017.1700200","journal-title":"IEEE Netw."},{"key":"4430_CR58","doi-asserted-by":"publisher","unstructured":"Abubakar, A., Pranggono, B.: Machine learning based intrusion detection system for software defined networks. In: 2017 Seventh International Conference on Emerging Security Technologies (EST), pp. 138\u2013143 (2017). https:\/\/doi.org\/10.1109\/EST.2017.8090413","DOI":"10.1109\/EST.2017.8090413"},{"issue":"2","key":"4430_CR59","doi-asserted-by":"publisher","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","volume":"18","author":"AL Buczak","year":"2016","unstructured":"Buczak, A.L., Guven, E.: A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Commun. Surv. Tutor. 18(2), 1153\u20131176 (2016). https:\/\/doi.org\/10.1109\/COMST.2015.2494502","journal-title":"IEEE Commun. Surv. Tutor."},{"issue":"10","key":"4430_CR60","doi-asserted-by":"publisher","first-page":"11994","DOI":"10.1016\/j.eswa.2009.05.029","volume":"36","author":"C-F Tsai","year":"2009","unstructured":"Tsai, C.-F., Hsu, Y.-F., Lin, C.-Y., Lin, W.-Y.: Intrusion detection by machine learning: a review. Expert Syst. Appl. 36(10), 11994\u201312000 (2009). https:\/\/doi.org\/10.1016\/j.eswa.2009.05.029","journal-title":"Expert Syst. Appl."},{"key":"4430_CR61","doi-asserted-by":"publisher","unstructured":"RT, K., Thamarai\u00a0Selvi, S., Govindarajan, K.: Ddos detection and analysis in sdn-based environment using support vector machine classifier. In: 2014 Sixth International Conference on Advanced Computing (ICoAC), pp. 205\u2013210 (2014). https:\/\/doi.org\/10.1109\/ICoAC.2014.7229711","DOI":"10.1109\/ICoAC.2014.7229711"},{"issue":"2","key":"4430_CR62","doi-asserted-by":"publisher","first-page":"311","DOI":"10.1007\/s10851-014-0523-2","volume":"51","author":"DA Lorenz","year":"2014","unstructured":"Lorenz, D.A., Pock, T.: An inertial forward-backward algorithm for monotone inclusions. J. Math. Imaging Vis. 51(2), 311\u2013325 (2014). https:\/\/doi.org\/10.1007\/s10851-014-0523-2","journal-title":"J. Math. Imaging Vis."},{"key":"4430_CR63","doi-asserted-by":"publisher","unstructured":"Hurley, T., Perdomo, J.E., Perez-Pons, A.: Hmm-based intrusion detection system for software defined networking. In: 2016 15th IEEE International Conference on Machine Learning and Applications (ICMLA), pp. 617\u2013621 (2016). https:\/\/doi.org\/10.1109\/ICMLA.2016.0108","DOI":"10.1109\/ICMLA.2016.0108"},{"issue":"9","key":"4430_CR64","doi-asserted-by":"publisher","first-page":"83","DOI":"10.3390\/fi10090083","volume":"10","author":"W Wang","year":"2018","unstructured":"Wang, W., Ke, X., Wang, L.: A HMM-r approach to detect l-DDoS attack adaptively on SDN controller. Future Internet 10(9), 83 (2018). https:\/\/doi.org\/10.3390\/fi10090083","journal-title":"Future Internet"},{"key":"4430_CR65","doi-asserted-by":"publisher","unstructured":"Boero, L., Marchese, M., Zappatore, S.: Support vector machine meets software defined networking in ids domain. In: 2017 29th International Teletraffic Congress (ITC 29), vol. 3, pp. 25\u201330 (2017). https:\/\/doi.org\/10.23919\/ITC.2017.8065806","DOI":"10.23919\/ITC.2017.8065806"},{"key":"4430_CR66","doi-asserted-by":"publisher","unstructured":"Nobakht, M., Sivaraman, V., Boreli, R.: A host-based intrusion detection and mitigation framework for smart home iot using openflow. In: 2016 11th International Conference on Availability, Reliability and Security (ARES), pp. 147\u2013156 (2016). https:\/\/doi.org\/10.1109\/ARES.2016.64","DOI":"10.1109\/ARES.2016.64"},{"key":"4430_CR67","doi-asserted-by":"publisher","unstructured":"Li, X., Yuan, D., Hu, H., Ran, J., Li, S.: DDoS detection in SDN switches using support vector machine classifier. In: Proceedings of the 2015 Joint International Mechanical, Electronic and Information Technology Conference. Atlantis Press, (2015). https:\/\/doi.org\/10.2991\/jimet-15.2015.63","DOI":"10.2991\/jimet-15.2015.63"},{"key":"4430_CR68","doi-asserted-by":"publisher","unstructured":"Wang, P., Chao, K.-M., Lin, H.-C., Lin, W.-H., Lo, C.-C.: An efficient flow control approach for sdn-based network threat detection and migration using support vector machine. In: 2016 IEEE 13th International Conference on e-Business Engineering (ICEBE), pp. 56\u201363 (2016). https:\/\/doi.org\/10.1109\/ICEBE.2016.020","DOI":"10.1109\/ICEBE.2016.020"},{"key":"4430_CR69","doi-asserted-by":"publisher","unstructured":"Stein, G., Chen, B., Wu, A.S., Hua, K.A.: Decision tree classifier for network intrusion detection with GA-based feature selection. In: Proceedings of the 43rd Annual Southeast Regional Conference on - ACM-SE 43. ACM Press, (2005). https:\/\/doi.org\/10.1145\/1167253.1167288","DOI":"10.1145\/1167253.1167288"},{"key":"4430_CR70","doi-asserted-by":"publisher","unstructured":"Ajaeiya, G.A., Adalian, N., Elhajj, I.H., Kayssi, A., Chehab, A.: Flow-based intrusion detection system for sdn. In: 2017 IEEE Symposium on Computers and Communications (ISCC), pp. 787\u2013793 (2017). https:\/\/doi.org\/10.1109\/ISCC.2017.8024623","DOI":"10.1109\/ISCC.2017.8024623"},{"key":"4430_CR71","doi-asserted-by":"publisher","unstructured":"Dayal, N., Srivastava, S.: An rbf-pso based approach for early detection of ddos attacks in sdn. In: 2018 10th International Conference on Communication Systems Networks (COMSNETS), pp. 17\u201324 (2018). https:\/\/doi.org\/10.1109\/COMSNETS.2018.8328175","DOI":"10.1109\/COMSNETS.2018.8328175"},{"key":"4430_CR72","doi-asserted-by":"publisher","unstructured":"Hyder, H.K., Lung, C.-H.: Closed-loop ddos mitigation system in software defined networks. In: 2018 IEEE Conference on Dependable and Secure Computing (DSC), pp. 1\u20136 (2018). https:\/\/doi.org\/10.1109\/DESEC.2018.8625125","DOI":"10.1109\/DESEC.2018.8625125"},{"issue":"2","key":"4430_CR73","doi-asserted-by":"publisher","first-page":"3336","DOI":"10.1016\/j.eswa.2008.01.039","volume":"36","author":"H-S Park","year":"2009","unstructured":"Park, H.-S., Jun, C.-H.: A simple and fast algorithm for k-medoids clustering. Expert Syst. Appl. 36(2), 3336\u20133341 (2009). https:\/\/doi.org\/10.1016\/j.eswa.2008.01.039","journal-title":"Expert Syst. Appl."},{"key":"4430_CR74","volume-title":"Software Defined Networks, Second Edition: A Comprehensive Approach","author":"P Goransson","year":"2016","unstructured":"Goransson, P., Black, C., Culver, T.: Software Defined Networks, Second Edition: A Comprehensive Approach, 2nd edn. Morgan Kaufmann Publishers Inc., San Francisco (2016)","edition":"2"},{"key":"4430_CR75","doi-asserted-by":"publisher","unstructured":"Latah, M., Toker, L.: Application of artificial intelligence to software defined networking: a survey. Indian J. Sci. Technol. (2016) https:\/\/doi.org\/10.17485\/ijst\/2016\/v9i44\/89812","DOI":"10.17485\/ijst\/2016\/v9i44\/89812"},{"issue":"2","key":"4430_CR76","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1049\/iet-net.2017.0212","volume":"7","author":"J Li","year":"2018","unstructured":"Li, J., Zhao, Z., Li, R.: Machine learning-based IDS for software-defined 5G network. IET Netw. 7(2), 53\u201360 (2018). https:\/\/doi.org\/10.1049\/iet-net.2017.0212","journal-title":"IET Netw."},{"key":"4430_CR77","doi-asserted-by":"publisher","DOI":"10.1002\/itl2.232","author":"S Rawat","year":"2020","unstructured":"Rawat, S., Srinivasan, A., Ravi, V., Ghosh, U.: Intrusion detection systems using classical machine learning techniques vs integrated unsupervised feature learning and deep neural network. Internet Technol. Lett. (2020). https:\/\/doi.org\/10.1002\/itl2.232","journal-title":"Internet Technol. Lett."},{"key":"4430_CR78","doi-asserted-by":"publisher","first-page":"65579","DOI":"10.1109\/ACCESS.2019.2916648","volume":"7","author":"M Usama","year":"2019","unstructured":"Usama, M., Qadir, J., Raza, A., Arif, H., Yau, K.A., Elkhatib, Y., Hussain, A., Al-Fuqaha, A.: Unsupervised machine learning for networking: Techniques, applications and research challenges. IEEE Access 7, 65579\u201365615 (2019). https:\/\/doi.org\/10.1109\/ACCESS.2019.2916648","journal-title":"IEEE Access"},{"key":"4430_CR79","doi-asserted-by":"publisher","unstructured":"Zanero, S., Savaresi, S.M.: Unsupervised learning techniques for an intrusion detection system. In: Proceedings of the 2004 ACM Symposium on Applied Computing - SAC \u201904. ACM Press, (2004). https:\/\/doi.org\/10.1145\/967900.967988","DOI":"10.1145\/967900.967988"},{"key":"4430_CR80","doi-asserted-by":"publisher","unstructured":"Barki, L., Shidling, A., Meti, N., Narayan, D.G., Mulla, M.M.: Detection of distributed denial of service attacks in software defined networks. In: 2016 International Conference on Advances in Computing, Communications and Informatics (ICACCI), pp. 2576\u20132581 (2016). https:\/\/doi.org\/10.1109\/ICACCI.2016.7732445","DOI":"10.1109\/ICACCI.2016.7732445"},{"key":"4430_CR81","doi-asserted-by":"publisher","first-page":"160536","DOI":"10.1109\/ACCESS.2019.2950945","volume":"7","author":"Y Xu","year":"2019","unstructured":"Xu, Y., Sun, H., Xiang, F., Sun, Z.: Efficient ddos detection based on k-fknn in software defined networks. IEEE Access 7, 160536\u2013160545 (2019). https:\/\/doi.org\/10.1109\/ACCESS.2019.2950945","journal-title":"IEEE Access"},{"key":"4430_CR82","doi-asserted-by":"publisher","first-page":"507","DOI":"10.1016\/j.procs.2016.02.095","volume":"78","author":"P Arora","year":"2016","unstructured":"Arora, P., Deepali, Varshney, S.: Analysis of k-means and k-medoids algorithm for big data. Procedia Comput. Sci. 78, 507\u2013512 (2016). https:\/\/doi.org\/10.1016\/j.procs.2016.02.095","journal-title":"Procedia Comput. Sci."},{"key":"4430_CR83","doi-asserted-by":"publisher","unstructured":"Silva, A., Wickboldt, J.A., Granville, L.Z., Schaeffer-Filho, A.: Atlantic: A framework for anomaly traffic detection, classification, and mitigation in sdn. In: NOMS 2016 - 2016 IEEE\/IFIP Network Operations and Management Symposium, pp. 27\u201335 (2016). https:\/\/doi.org\/10.1109\/NOMS.2016.7502793","DOI":"10.1109\/NOMS.2016.7502793"},{"key":"4430_CR84","doi-asserted-by":"publisher","unstructured":"Huang, Y., Ma, X., Fan, X., Liu, J., Gong, W.: When deep learning meets edge computing. In: 2017 IEEE 25th International Conference on Network Protocols (ICNP), pp. 1\u20132 (2017). https:\/\/doi.org\/10.1109\/ICNP.2017.8117585","DOI":"10.1109\/ICNP.2017.8117585"},{"key":"4430_CR85","unstructured":"Nguyen, T.T., Reddi, V.J.: Deep reinforcement learning for cyber security. CoRR abs\/1906.05799 (2019) arXiv:1906.05799"},{"key":"4430_CR86","doi-asserted-by":"publisher","unstructured":"Min, E., Long, J., Liu, Q., Cui, J., Cai, Z., Ma, J.: SU-IDS: A semi-supervised and unsupervised framework for network intrusion detection. In: Cloud Computing and Security, pp. 322\u2013334. Springer, (2018). https:\/\/doi.org\/10.1007\/978-3-030-00012-7_30","DOI":"10.1007\/978-3-030-00012-7_30"},{"key":"4430_CR87","doi-asserted-by":"publisher","unstructured":"Ferrag, M.A., Maglaras, L.A., Janicke, H., Smith, R.: Deep learning techniques for cyber security intrusion detection : A detailed analysis. BCS Learning & Development, (2019). https:\/\/doi.org\/10.14236\/ewic\/icscsr19.16","DOI":"10.14236\/ewic\/icscsr19.16"},{"issue":"12","key":"4430_CR88","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1109\/mcom.2017.1700246","volume":"55","author":"Y He","year":"2017","unstructured":"He, Y., Yu, F.R., Zhao, N., Leung, V.C.M., Yin, H.: Software-defined networks with mobile edge computing and caching for smart cities: A big data deep reinforcement learning approach. IEEE Commun. Mag. 55(12), 31\u201337 (2017). https:\/\/doi.org\/10.1109\/mcom.2017.1700246","journal-title":"IEEE Commun. Mag."},{"key":"4430_CR89","doi-asserted-by":"publisher","unstructured":"Tang, T.A., Mhamdi, L., McLernon, D., Zaidi, S.A.R., Ghogho, M.: Deep learning approach for network intrusion detection in software defined networking. In: 2016 International Conference on Wireless Networks and Mobile Communications (WINCOM), pp. 258\u2013263 (2016). https:\/\/doi.org\/10.1109\/WINCOM.2016.7777224","DOI":"10.1109\/WINCOM.2016.7777224"},{"key":"4430_CR90","doi-asserted-by":"publisher","unstructured":"Tang, T.A., Mhamdi, L., McLernon, D., Zaidi, S.A.R., et al.: Deep Recurrent Neural Network for Intrusion Detection in SDN-based Networks. In: 2018 4th IEEE Conference on Network Softwarization and Workshops (NetSoft), pp. 202\u2013206 (2018). https:\/\/doi.org\/10.1109\/NETSOFT.2018.8460090","DOI":"10.1109\/NETSOFT.2018.8460090"},{"issue":"2","key":"4430_CR91","first-page":"76","volume":"2","author":"R Gre\u017eo","year":"2018","unstructured":"Gre\u017eo, R.: Dos detection using machine learning and software defined networks. Security & Future 2(2), 76\u201379 (2018)","journal-title":"Security & Future"},{"key":"4430_CR92","doi-asserted-by":"publisher","first-page":"21954","DOI":"10.1109\/ACCESS.2017.2762418","volume":"5","author":"C Yin","year":"2017","unstructured":"Yin, C., Zhu, Y., Fei, J., He, X.: A deep learning approach for intrusion detection using recurrent neural networks. IEEE Access 5, 21954\u201321961 (2017). https:\/\/doi.org\/10.1109\/ACCESS.2017.2762418","journal-title":"IEEE Access"}],"container-title":["Cluster Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-024-04430-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10586-024-04430-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-024-04430-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,9]],"date-time":"2024-09-09T19:25:33Z","timestamp":1725909933000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10586-024-04430-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,25]]},"references-count":92,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2024,10]]}},"alternative-id":["4430"],"URL":"https:\/\/doi.org\/10.1007\/s10586-024-04430-6","relation":{},"ISSN":["1386-7857","1573-7543"],"issn-type":[{"value":"1386-7857","type":"print"},{"value":"1573-7543","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,4,25]]},"assertion":[{"value":"24 August 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 March 2024","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 March 2024","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 April 2024","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have not disclosed any competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}]}}